CSE Annual Report 2025-26 Discloses 3216 Cyber Incidents Responded to and Disruption of 10 Ransomware Groups Targeting Canada
In its 2025-2026 Annual Report released June 30, Canada's Communications Security Establishment said its
CSE's disclosure of coordinated action against 10 ransomware groups, rather than isolated takedowns, indicates offensive cyber operations are becoming a standing complement to defensive incident response. The gap between that aggregate figure and The Record's narrower three-target account, the only independent secondary reporting against CSE's own primary release, suggests Ottawa is calibrating what it publicly attributes to manage diplomatic exposure while still signaling capability. The aggregate may also reflect joint operations with law enforcement rather than ten unilateral CSE actions, a distinction the report leaves unresolved. Subsequent reporting narrowed that aggregate to identifiable categories, drug trafficking and extremist-network targets, for the first time. Thirteen quantum-cryptography briefings alongside 3,216 incident responses indicate CSE now treats post-quantum migration as an operational priority, with federal institutions and infrastructure operators bearing the transition burden.
3 sources
- Canada's CSE report details rising cyber threats, ransomware investigations, critical infrastructure protection efforts -
Industrial Cyber - Canadian spy agency reports hacking three criminal groups in 2025 -
The Record (Recorded Future News) - Communications Security Establishment Canada releases its 2025-2026 Annual Report -
Communications Security Establishment Canada / Canada.ca